Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ
  Verisign µµ¸ÞÀε¶Á¡°ü·Ã bind ¼³Á¤ ÀÛ¼ºÀÏ : 2003/09/30 01:45
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 7607
     
    Á¦  ¸ñ : Verisign µµ¸ÞÀε¶Á¡°ü·Ã bind ¼³Á¤
    ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2003.9.29(¿ù)

    ÃÖ±Ù¿¡ º£¸®»çÀο¡¼­
    Á¸ÀçÇÏÁö ¾Ê´Â .com, .net µµ¸ÞÀÎ(À̸¦Å׸é asdfghjkasa.net)¿¡ ´ëÇØ
    º£¸®»çÀÎÀÇ sitefinder ÁÖ¼Ò¸¦ ¾Ë·ÁÁÖ´Â ²ûÂïÇÑ(?) ÀÏÀ» ¹ú·È½À´Ï´Ù.

    À̸¦ ÇØ°áÇϱâ À§ÇÑ bind ÆÐÄ¡°¡ ³ª¿Ô°í
    KreonetÀÇ ¼­»ó¿ë´ÔÀÌ 'VerisignÀÇ µµ¸ÞÀÎ µ¶Á¡°ú ½ºÆÔ ÇÊÅ͸µ'À̶ó´Â Á¦¸ñÀ¸·Î
    han.comp.mailÀ» Æ÷ÇÔÇÑ 3°³ ´º½º±×·ì¿¡ bind ÆÐÄ¡ ¹æ¹ýÀ» Æ÷½ºÆÃÇß½À´Ï´Ù.

    Æ÷½ºÆÃµÈ ±Û : http://coffeenix.net/board_view.php?bd_code=81

    ¼³Á¤°ü·Ã Áú¹®ÀÌ ¿Ã¶ó¿Â ÅͶó Àû´çÈ÷ Á¤¸®ÇÏ¿© ¿Ã¸³´Ï´Ù.

    1) named.conf ¼³Á¤

    ÀÌ ÆÐÄ¡ Àû¿ëÈÄ named.conf ¼³Á¤¿¡ ´ëÇØ ¼³¸íÇÏ°Ú½À´Ï´Ù.

    verisign°ú Á÷Á¢ÀûÀ¸·Î °ü·ÃÀÖ´Â .com, .net °ü·ÃÇؼ­
    /etc/named.conf¿¡ ´ÙÀ½ 2 ÁÙÀ» Ãß°¡ÇÕ´Ï´Ù.

    zone "com" { type delegation-only; };
    zone "net" { type delegation-only; };

    2) Å×½ºÆ®

    dig À¸·Î ³×ÀÓ¼­¹ö¸¦ ·ÎÄ÷ΠÁöÁ¤ÇÑ ´ÙÀ½ Å×½ºÆ®¸¦ Çغ¾´Ï´Ù.


    # dig @localhost adkadadadada.net (ù¹ø°)
    ...
    ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 18791
    ...
    # dig @localhost kldp.net (µÎ¹ø°)
    ...
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56475
    ...



    ù¹ø° µ¥½ºÆ®¿¡¼­  NXDOMAINÀ̶ó°í ³ª¿À¸é Á¤»óÀûÀ¸·Î 󸮵ǰí ÀÖ½À´Ï´Ù.
    NXERROR¶ó°í ³ª¿À¸é´Ù¸é named.conf ¼³Á¤À» ´Ù½Ã Çѹø º¸½Ã°í, Àç½ÇÇàÇß´ÂÁöµµ È®ÀÎ.
    µÎ¹ø° Å×½ºÆ®¿¡¼­ NXERRORÀ̶ó°í ³ª¿À°í kldp.net IP°¡ ³ª¿À¸é Á¤»ó

    * Verisign °ü·Ã ±ÛÀº slashdot ¿¡¼­ Àо¼¼¿ä.

    - Resolving Everything: VeriSign Adds Wildcards
    ¡¡http://slashdot.org/article.pl?sid=03/09/16/0034210
    - ICANN Asks VeriSign To Stop DNS Wildcarding
    ¡¡http://slashdot.org/article.pl?sid=03/09/22/0443224


    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ / URL : http://coffeenix.net/board_view.php?bd_code=84